unreachable.cloud
  • Communities
  • Create Post
  • Create Community
  • heart
    Support Lemmy
  • search
    Search
  • Login
  • Sign Up
not_IO@lemmy.blahaj.zone to linuxmemes@lemmy.worldEnglish · 1 day ago

can someone explain this to me? 🫪

lemmy.blahaj.zone

message-square
22
fedilink
266

can someone explain this to me? 🫪

lemmy.blahaj.zone

not_IO@lemmy.blahaj.zone to linuxmemes@lemmy.worldEnglish · 1 day ago
message-square
22
fedilink
  • NullPointerException@lemmy.ca
    link
    fedilink
    arrow-up
    34
    ·
    1 day ago

    How would a firewall be related to this? A firewall would block/allow the ports 80/443 from certain sources. That’s it. Whatever is happening here it’s related to OS permissions and web server configuration.

    • AudaciousArmadillo@piefed.blahaj.zone
      link
      fedilink
      English
      arrow-up
      10
      ·
      24 hours ago

      Because enterpise firewalls suck ass. If you follow some security researchers on fedi it is shockingly common. Like every week there is an unauth RCE to these things and usually its …/. Is it absurd that a companies expensive first line defense is less secure than your mum’s laptop? I’m sure it is “AI” ready though!

    • chamomile@piefed.blahaj.zone
      link
      fedilink
      English
      arrow-up
      52
      ·
      1 day ago

      It’s referring to a Web Application Firewall.

      • AudaciousArmadillo@piefed.blahaj.zone
        link
        fedilink
        English
        arrow-up
        1
        arrow-down
        4
        ·
        24 hours ago

        Unlikely.

        • libewa@feddit.org
          link
          fedilink
          arrow-up
          1
          ·
          8 hours ago

          Very likely. Or, at least what the thread commenter meant. There’s other programs vulnerable to …/, but it’s mostly some kind of Application Firewall, one that inspects the message itself.

    • LastYearsIrritant@sopuli.xyz
      link
      fedilink
      English
      arrow-up
      14
      arrow-down
      1
      ·
      1 day ago

      The point of the comic is that people expect a firewall to protect them from attacks, but then the attack comes in as a path traversal and the firewall does nothing.

    • foggy@lemmy.world
      link
      fedilink
      arrow-up
      14
      arrow-down
      4
      ·
      1 day ago

      Frankly to suggest that an enterprise firewall would be susceptible to a simple path traversal attack is insane. Unless there’s the most embarrassing news story of the decade im missing? That kind of input validation is baked into basically everything these days.

      Maybe you’ll land input validation using quadruple URL encoded ‘…/’ or something but even still I’d doubt that.

      So the person who replied to you is 100% correct in what it’s about, but it doesn’t really explain the comic. Unless it was made in like a decade ago.

      • Manny_Folf@pawb.social
        link
        fedilink
        arrow-up
        3
        ·
        edit-2
        19 hours ago

        See this comment https://feddit.org/comment/14642166 Plus https://www.sentinelone.com/vulnerability-database/cve-2026-34790/ Granted by no means trivial methods

      • helvetpuli@sopuli.xyz
        link
        fedilink
        arrow-up
        10
        arrow-down
        1
        ·
        1 day ago

        It’s pretty common in a killchain following a server side request forgery since the traffic isn’t seem by the WAF.

        Example: https://github.com/watchtowrlabs/watchTowr-vs-Oracle-E-Business-Suite-CVE-2025-61882

        • foggy@lemmy.world
          link
          fedilink
          arrow-up
          2
          ·
          1 day ago

          It really is not common in the common era.

          E-business suite is not a firewall. Anyone that was using it as one when this cve hit about a year ago wouldnt have qualified as “enterprise” to any required insurance, even then.

          Anyone who was using it as such was/is drowning in so much tech debt that, like, if you work there, leave. Yesterday.

          • helvetpuli@sopuli.xyz
            link
            fedilink
            arrow-up
            1
            ·
            2 hours ago

            Of course it isn’t.

            It was behind a WAF. But that didn’t matter for the path traversal in this attack.

    • floquant@lemmy.dbzer0.com
      link
      fedilink
      arrow-up
      2
      ·
      23 hours ago

      Layer 7 firewalls are a thing

      • xavier666@lemmy.umucat.day
        link
        fedilink
        English
        arrow-up
        2
        ·
        13 hours ago

        Layer 7 firewall sounds so wrong

        • floquant@lemmy.dbzer0.com
          link
          fedilink
          arrow-up
          1
          ·
          12 hours ago

          That’s why it’s usually called a WAF (Web Application Firewall), although you can also have L7 firewall for non-web applications (SMTP, SQL, whatever)

linuxmemes@lemmy.world

linuxmemes@lemmy.world

Subscribe from Remote Instance

Create a post
You are not logged in. However you can subscribe from another Fediverse account, for example Lemmy or Mastodon. To do this, paste the following into the search field of your instance: [email protected]

Hint: :q!


Sister communities:
  • [email protected]
  • [email protected]
  • [email protected]
  • [email protected]

Community rules (click to expand)

1. Follow the site-wide rules
  • Instance-wide TOS: https://legal.lemmy.world/tos/
  • Lemmy code of conduct: https://join-lemmy.org/docs/code_of_conduct.html
2. Be civil
  • Understand the difference between a joke and an insult.
  • Do not harrass or attack users for any reason. This includes using blanket terms, like “every user of thing”.
  • Don’t get baited into back-and-forth insults. We are not animals.
  • Leave remarks of “peasantry” to the PCMR community. If you dislike an OS/service/application, attack the thing you dislike, not the individuals who use it. Some people may not have a choice.
  • Bigotry of any kind will not be tolerated. This is an LGBTQ+-friendly community – if that is a problem for you, you should leave.
3. Post Linux-related content
  • Including Unix and BSD.
  • Non-Linux content is acceptable as long as it makes a reference to Linux. For example, the poorly made mockery of sudo in Windows.
  • No porn, no politics, no trolling or ragebaiting.
  • Don’t come looking for advice, this is not the right community.
4. No recent reposts
  • Everybody uses Arch btw, can’t quit Vim, <loves / tolerates / hates> systemd, and wants to interject for a moment. You can stop now.
5. 🇬🇧 Language/язык/Sprache
  • This is primarily an English-speaking community. 🇬🇧🇦🇺🇺🇸
  • Comments written in other languages are allowed.
  • The substance of a post should be comprehensible for people who only speak English.
  • Titles and post bodies written in other languages will be allowed, but only as long as the above rule is observed.
6. (NEW!) Regarding public figures

We all have our opinions, and certain public figures can be divisive. Keep in mind that this is a community for memes and light-hearted fun, not for airing grievances or leveling accusations.

  • Keep discussions polite and free of disparagement.
  • We are never in possession of all of the facts. Defamatory comments will not be tolerated.
  • Discussions that get too heated will be locked and offending comments removed.

 

Please report posts and comments that break these rules!


Important: never execute code or follow advice that you don’t understand or can’t verify, especially here. The word of the day is credibility. This is a meme community – even the most helpful comments might just be shitposts that can damage your system. Be aware, be smart, don’t remove France.

Visibility: Public
globe

This community can be federated to other instances and be posted/commented in by their users.

  • 2.17K users / day
  • 4.64K users / week
  • 8.56K users / month
  • 16.5K users / 6 months
  • 1 local subscriber
  • 32.6K subscribers
  • 2.39K Posts
  • 123K Comments
  • Modlog
  • mods:
  • Kevin@lemmy.world
  • zephyr@lemmy.world
  • Err(()).unwrap()@lemmy.world
  • BE: 0.19.5
  • Modlog
  • Instances
  • Docs
  • Code
  • join-lemmy.org